PT-2026-108769 · Linux · Linux

CVE-2026-98383

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Disallow bpf skb pull data() for LWT SEG6LOCAL
An LWT SEG6LOCAL program can invalidate its cached SRH with bpf lwt seg6 adjust srh() and then call bpf skb pull data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer.
Disallow bpf skb pull data() for LWT SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt out func proto().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98383

Affected Products

Linux